CVE-2019-3569

HHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could allow a malicious individual unintended direct access to the application, which could result in information disclosure. This issue affects versions 4.3.0, 4.4.0, 4.5.0, 4.6.0, 4.7.0, 4.8.0, versions 3.30.5 and below, and all versions in the 4.0, 4.1, and 4.2 series.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.0.3:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.0.4:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.1.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.2.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.3.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.4.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.5.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.6.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.7.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.8.0:*:*:*:*:*:*:*

History

21 Nov 2024, 04:42

Type Values Removed Values Added
References () https://github.com/facebook/hhvm/commit/97ef580ec2cca9a54da6f9bd9fdd9a455f6d74ed - Patch, Third Party Advisory () https://github.com/facebook/hhvm/commit/97ef580ec2cca9a54da6f9bd9fdd9a455f6d74ed - Patch, Third Party Advisory
References () https://hhvm.com/blog/2019/06/10/hhvm-4.9.0.html - Release Notes, Vendor Advisory () https://hhvm.com/blog/2019/06/10/hhvm-4.9.0.html - Release Notes, Vendor Advisory

Information

Published : 2019-06-26 15:15

Updated : 2024-11-21 04:42


NVD link : CVE-2019-3569

Mitre link : CVE-2019-3569

CVE.ORG link : CVE-2019-3569


JSON object : View

Products Affected

facebook

  • hhvm
CWE
CWE-552

Files or Directories Accessible to External Parties

CWE-668

Exposure of Resource to Wrong Sphere